Incoming Apprenti Ingénieur Cybersécurité @ Société Générale (Oct. 2026) | MSc MBA @ Epitech Paris
Ancien Alternant Data & Automation @ SNCF Voyageurs | L3 Computer Science @ Université Gustave Eiffel
🌐 Portfolio : vincent-p-essy.github.io
- 🔐 Interested in backend, systems and cybersecurity
- 🐧 Linux user
Je ne construis pas des projets vitrines, je conçois des systèmes d'infrastructure et de sécurité applicative résilients, interconnectés et prêts pour la production.
📄 I built an automated DORA compliance engine in Python — here's what I learned about regulatory engineering
How I automated 200–400h of manual audit work using OPA/Rego policies, evidence vaults with immutability triggers, and CI/CD gates — with a deliberate 75/100 score to prove the detection actually works.
Plutôt que des dépôts isolés, mon GitHub héberge un écosystème complet de détection, corrélation et traitement des incidents, conçu selon les principes de la Clean Architecture et du TDD.
[ pcap-analyzer ] (C Parser)
│
▼ (JSON Flux)
[ threat-correlation-engine ] (YAML Rules) ◄─── [ vuln-digest ] (Threat Intel)
│
▼ (Trigger)
[ incident-tracker-api ] (Flask REST RBAC) ◄─── [ llm-triage ] (AI Guardrails)
│
▼
[ cyber-dashboard ] (MTTD / MTTR Real-time metrics)
[ dora-compliance-engine ] ──────────────────────► CI/CD Gate (DORA / ISO 27001)
- pcap-analyzer : Analyseur réseau écrit en C pur. Détecteurs : Port scan, ARP spoofing, DNS tunneling. Output JSON.
- threat-correlation-engine : Pipeline Loader → Correlator → Dispatcher sur fenêtres glissantes et règles YAML.
- vuln-digest : Threat Intel quotidien NVD + CISA KEV + GitHub Advisories, scoring CVSS v3 bancaire, rapport HTML.
- security-audit-logger : Clean Architecture .NET 8, TDD xUnit, CI/CD Trivy, Docker non-root.
- incident-tracker-api : API REST Flask/PostgreSQL, JWT, RBAC 3 rôles, 97% test coverage.
- llm-triage : Triage LLM sous contraintes DORA/PCI-DSS, prompts Jinja2 structurés.
- dora-compliance-engine : Conformité DORA/ISO 27001 automatisée. OPA/Rego, evidence vault immuable, gate CI/CD, drift scoring. 97 tests, 96% coverage. Article Medium →
- ci-security-gate : GitHub Action centralisée — entropie Shannon, pip-audit, Dockerfile lint.
- cyber-dashboard : Console MTTD/MTTR temps réel, mode démo standalone.
- SNCF Voyageurs (Transilien) : Scénar'Express — application d'aide à la décision temps réel au COT. Power BI, automatisation.
- Apex 3D : Co-fondateur e-commerce, site complet HTML/CSS/JS + chatbot IA.
- Cyber : Google Cybersecurity Professional, Fortinet FCF, Splunk SOC Essentials, Cisco Cyber.
- Langages : C, .NET 8 (C#), Python (Flask), Bash, SQL (PostgreSQL), Java, JavaScript.
- Ops : Docker, GitHub Actions CI/CD, Linux (Debian), Wireshark.
I enjoy working close to the system (C, Linux) and building backend/data applications (Python, SQL).
Feel free to contact me for any opportunity.


